“Ask Sarah” is not a knowledge-management strategy

Informal handovers and generic AI tools leave regulated organisations with confident answers nobody can trace. Regulated work needs AI with citations, audit trails and human sign-off built in.

5 min read
Read with AI

Open in

ChatGPT Claude Perplexity

This page

Copied to clipboard
“Ask Sarah” is not a knowledge-management strategy

The only thing faster than the speed of thought is the speed at which we forget what we learn. This is especially true when a departing colleague (who has been with your company, say, five years or more) emails you their handover document after ‘a brief chat to get you up to speed.’

Caltech researchers have quantified the speed of human thought at a rate of 10 bits per second. However, our bodies' sensory systems gather data about our environments at a rate of a billion bits per second, which is 100 million times faster than our thought processes. This new study begs the question: Why can we only think one thing at a time while our sensory systems process thousands of inputs at once?

The tabloid front-page version of forgetting

If something goes wrong in building safety, healthcare, or aviation, it may lead to a public investigation. In a worst-case scenario, you end up on the front page of the Daily Mail. All because the "brief handover chat" was vague or had gaps, and the person you could check with had left in March.

For many organisations, training or CPD becomes the answer to making sure people get hold of all the knowledge they need. Every company I have worked for has had a training budget and induction program. Few of them deal with the question of what happens to shiny-new knowledge when the employees return to their day jobs. Ebbinghaus’ forgetting curve shows that without reinforcement, people forget about half of what they learn within days. And whatever people have learned in training needs to survive both a normal day or a Monday from hell.

Knowledge handed down by half-memory is dangerous. You’ll know how that affects two workers on a busy Monday at 10.47 am. One asks someone else how to handle a process, and that person half-remembers. Suddenly 'the way we do things around here' is baked in stone. Which works fine. Until it doesn't. And that’s because no one is around to notice that the informal answer is not the right one.

I've worked in UK social housing for most of my career, so that's my reference point. But the gap between official procedures and frontline reality can happen in any regulated or complex operating environment.

In short, can we be sure that a stressed worker is able to find the right answer? Understand it? Trust that it is accurate and up-to-date?

The instant noodles approach

That's where generative AI is being asked to do something beyond its power. When we need a quick answer these days, our impulse is to open up Copilot or ChatGPT and, yes, we have the answer in seconds. Although it’s a bit like expecting instant noodles to fulfill your daily need of five fruits and veggies. We have to question the value of ChatGPT-based data in a highly regulated environment. AI help needs to be based on policies in place and the latest regulatory guidance. Then it must be something that an auditor would accept as a source.

If you want to see how this headache can develop, then take a look at Gateway 2, a tight statutory checkpoint under the UK’s Building Safety Act 2022. For Higher-Risk Buildings over 18 meters high, this is overseen by the Building Safety Regulator. Developers must submit fully coordinated and compliant designs prior to construction, and failure to provide information can result in costly work stoppages.

But CAST Consultancy found 78% of the submissions needed more information before they could be approved. Despite having good resources and expert teams, these organisations have been forced back to the drawing board. It’s a sobering reminder that internal business expertise isn’t the same as getting the right bit of knowledge to the right hands at the right time.

If experienced teams with committed resources are failing to keep up, imagine what happens when a generic AI tool (trained on wide internet data, with no access to the specific regulatory framework and no audit trail) tries to fill that gap.

It’s not possible to expect generic AI tools to understand processes that they were never designed for. These tools will always reply with 100% confidence, but you will be hard-pressed to know how they validate their data. This leaves you with a dangerous knowledge gap that has a convincing voice. A bit like that person in a meeting who sounds so authoritative that no one thinks to question them.

Properly fit for purpose

In case you are thinking all this sounds like doom and gloom, I am seeing really good examples of AI built with governance as a fundamental principle. Newham Council’s Domus project has been developed in partnership with the UK Center for AI in the Public Sector. It’s properly fit for purpose.

Newham’s AI lead, Nathan Nagaiah, realised that residents were using ChatGPT to write complaints. Some council officers were then using generic AI to respond. That’s a nasty case of ‘two machines talking to each other.’

Nathan’s alternative for Newham is a purpose-built AI. It is a far safer option, as Nathan says: “It’s better to build a custom AI agent that will actually reply with the correct information, issue a case reference number and refer to council policies.” —Ella Jessel, The London borough using AI to solve temporary accommodation allocations, Inside Housing, May 2026

Generic AI is not just a housing problem

If we leave housing for a moment and look at pharma, we find much the same problem. Arun Ramakrishnan, co-founder and CTO of LogicFlo AI, makes the case in Forbes that generic AI agents (built for speed and broad usability) will never hit the mark in sectors like pharma, life sciences, finance and government. These are all fields where “good enough” is a liability. Talking about some of the issues with generic AI, he says,

“Now you have a system making decisions, retrieving information, calling tools, storing memory, generating outputs, maybe even triggering downstream actions. Somewhere, later, somebody is going to ask: “Okay, but how exactly did this happen?” A fluent answer by itself doesn’t help much if nobody can verify where it came from.” —Arun Ramakrishnan, Why Generic AI Agents Don’t Work In Regulated Industries, Forbes, June 2026

The distance between certain and accurate

Across these articles, and across very different sectors, the same problems keep coming up when generic AI is used in regulated environments.

• It can sound certain when it is wrong. There is often no reliable way to say, “I don’t know” or flag uncertainty.

• You can't always see where an answer came from. Without an audit trail, it is hard to reconstruct what happened for a regulator, auditor, or colleague.

• It may not be grounded in the rules that matter. Generic AI does not automatically know which version of a policy, regulation, or firm-specific rule applies today.

• Data can end up where it shouldn't. Tools can create problems around data residency, processing agreements, and professional secrecy.

• AI can spread faster than the controls around it. Shadow use and expanding permissions create new access-control risks.

• The firm still owns the outcome. When AI gets it wrong, accountability ultimately sits with the regulated organisation.

The conclusion is consistent. Regulated environments need AI with guardrails built in. That means traceable sources, citations, human sign-off, robust logs and domain-specific constraints.

Generic AI still has its place for drafting, summarising and low-stakes research.

But when the answer could affect a resident, patient, customer, regulator or your organisation, “probably right” isn't good enough.